CVE-2026-105400
Received Received - Intake

Resource Leak in ImageMagick via Malicious Magick Script

Vulnerability report for CVE-2026-105400, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

ImageMagick before 7.1.2-31 contains a resource leak vulnerability that allows attackers to leave file pointers open by supplying a crafted magick script. Attackers can process malicious magick scripts to leak file descriptors, potentially exhausting resources and causing denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ImageMagick ImageMagick 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-775 The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a resource leak in ImageMagick versions before 7.1.2-31. Attackers can exploit it by providing a specially crafted magick script that leaves file pointers open. This causes the application to exhaust system resources, potentially leading to denial of service.

Detection Guidance

To detect this vulnerability, monitor for unusually high file descriptor usage or processes with open file pointers after executing ImageMagick operations. Check for processes using ImageMagick with commands like 'lsof -p <PID>' or 'ps aux | grep magick'. Review logs for repeated ImageMagick script executions that may indicate resource leaks.

Impact Analysis

The vulnerability can cause system resource exhaustion, leading to degraded performance or complete denial of service. It requires no privileges or user interaction to exploit, making it accessible to remote attackers.

Compliance Impact

This vulnerability primarily causes resource exhaustion and denial-of-service conditions by leaving file pointers open. It does not directly involve unauthorized data access or disclosure, which are key concerns for GDPR and HIPAA. However, resource exhaustion could indirectly impact system availability, potentially affecting service levels required by these regulations.

Mitigation Strategies

Upgrade ImageMagick to version 7.1.2-31 or later immediately. Remove or restrict access to untrusted magick scripts. Monitor system resources for signs of exhaustion. Apply patches from official ImageMagick releases or trusted sources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105400. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart